Certificate event customization

Hello Developer

I have a requirement at my organization for the certificate event,
we need to create a certificate during the mover process, I am able to create a certificate during the mover process by adding the same filter for mover process.

main requirement is within the certificate event process, where the approval should go to only to the new manager and later it should go to the entitlement owner for the approval.
as this requirement should be similar to the access request workflow. where we have the same approach on it.

with the default certificate event it is going to both manager old and new manager of the user.

attaching the current configuration for references.

please suggest me how can we customizes the approval workflow in the certificate event.

thanks in advance.
Riyazuddin

If you plan to use Certification Events then for manager change it will always assign the approvals to old and new manager. If you need to change this behavior then you will have to create a Lifecycle Event and attach a workflow that needs to be customized to kick off certification s using APIs. Here is a thread which has sample for your reference.
https://community.sailpoint.com/t5/IdentityIQ-Forum/Launching-Certification-Using-IIQ-API/m-p/108442

Only possible via LifeCycle event with custom workflow to achieve you requirement and you can use spiltApproval for entitlement owner approve certification event workflow(OOTB) can’t be customized

If Attribute Change event already configured, add additional condition to check manager attribut or create new event for manager change

@Riyazuddin99 we achieved this with a custom rule in the past. Mover worflow was setting an identity attribute and we used to had a separate rule runner task to launch a single cert campaign for the given day for all users with movers.

To add an application approval post manager, you can write a CertificationSignOffApprover rule which will take care of adding another layer of approval.

Hello @neel193 ,

can you please share a sample code for certificationsignoff approver rule.

@Riyazuddin99 Here are couple of example of CertificationSignOffApprover rules from the Rules doc:

This example CertificationSignOffApprover rule forwards the certification to the certifier’s manager for approval. This process continues with this rule until the certifier does not have a manager (e.g. all the way up the managerhierarchy).

import sailpoint.object.Identity;

// This requires approval all the up the manager hierarchy. Once we get

// to the most senior manager, approvals stop.

Identity identity = certifier.getManager();

if (identity != null) {

Map results = new HashMap();

results.put("identity", identity);

return results;

} else {

return null;

}

Since every signer is added to the certificationSignOffHistory immediately after the certificationSignOffApprover rule runs, this rule could be limited to only require one level of secondary signoff by checking the certification signoff history like this:

import sailpoint.object.Certification;

import sailpoint.object.Identity;

// if cert signoff history indicates it has already been signed off once,

// do not submit to any other levels of

approval

List history = certification.getSignOffHistory();

if (history == null || history.isEmpty()){

Identity identity = certifier.getManager();

Map results = new HashMap();

results.put("identity", identity);

return results;

}

else

return null;

}

Hello @neel193 ,

I have added the below code to redirect the certificate towards the entitlement owner.
but it’s not redirect towards that.
and right after we click on sign off the cert is getting closed.

  import sailpoint.tools.Util;
  import sailpoint.object.ApprovalItem;
  import sailpoint.object.ApprovalSet;

  private String getManagedAttributeOwner(Application app, String name, String value ) {
    String owner = null;
    ManagedAttribute ma = ManagedAttributer.get(context, app.getId(), name, value);
    if ( ma != null ) {
      Identity maOwner = ma.getOwner();
      if ( maOwner != null ) 
        owner = maOwner.getName();
    }
    return owner;
  }

can you please have a look on this.

Thanks
Riyazuddin

@Riyazuddin99 Have you printed the logs to make sure your rule is being triggered or not?

Hello @neel193 ,

nope I haven’t checked the loggs
can you shared the logger if you know for both certificate and rules.

@Riyazuddin99 just add log.error(“your message key::”+your object name); in your rule .

 import sailpoint.tools.Util;
  import sailpoint.object.ApprovalItem;
  import sailpoint.object.ApprovalSet;

log.error("rule started");
  private String getManagedAttributeOwner(Application app, String name, String value ) {
log.error("inside method");
    String owner = null;
    ManagedAttribute ma = ManagedAttributer.get(context, app.getId(), name, value);
    if ( ma != null ) {
      Identity maOwner = ma.getOwner();
      if ( maOwner != null ) 
        owner = maOwner.getName();
    }
log.error("owner::"+owner);
    return owner;
  }

I have added few, feel free to add more based on your requirements.